Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-54424 — Exploiting Parsec for Windows to gain SYSTEM privileges | Kitploit
Tools/GitHubGitHub/tomadimitrie/cve-2026-54424
Privilege EscalationVulnerability AnalysisExploitationLateral MovementPost-ExploitationCommand and ControlRemote Access ToolBinary Exploitation
GitHubtomadimitrie/cve-2026-54424

CVE-2026-54424

Exploiting Parsec for Windows to gain SYSTEM privileges

View Repository
1 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-54424

Exploiting Parsec for Windows versions < 150-104a to gain:

  • Remote code execution as SYSTEM
  • Arbitrary file read as SYSTEM
  • NTLM hash capture for SYSTEM

The exploits stem from the same vulnerability, but the actual paths diverge.

Technical writeup: https://www.tomadimitrie.dev/blog/CVE-2026-54424

Advisory: https://support.parsec.app/hc/en-us/articles/50612943726612-CVE-2026-54424

NIST: https://nvd.nist.gov/vuln/detail/CVE-2026-54424

Note: The RCE exploit is pretty flaky, but the others work perfectly 100% of the time. The RCE exploits a very tight race condition and tries to extend the race window using big files. So, on modern and performant systems the files might need to be really big. For testing purposes try a VM with 1 core and 1 GB RAM.

Download Tool